What is CVE-2026-16547?
CVE-2026-16547 is a security flaw in the REST API Log WordPress plugin. Versions before 1.7.1 fail to bind the token protecting the log download feature to the specific log entry and do not check user capabilities, allowing unauthenticated users with any such token to download logged REST API requests. It is recommended to update the plugin to at least version 1.7.1.
Azərbaycanca: CVE-2026-16547, REST API Log WordPress plaginində token təhlükəsizliyi zəifliyidir. 1.7.1 versiyasından əvvəlki plaginlər, log yükləmə xüsusiyyətində token-i log qeydinə bağlamır və istifadəçi icazələrini yoxlamır, bu da autentifikasiya olunmayan şəxslərə token ilə loglanmış REST API sorğularını yükləməyə imkan verir. Bu zəiflikdən qorunmaq üçün plaqini ən azı 1.7.1 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which WordPress plugin is affected by CVE-2026-16547?
This vulnerability affects the REST API Log plugin.
What should be done to protect against CVE-2026-16547?
It is recommended to update the plugin to at least version 1.7.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.